VYPR
Medium severity4.7NVD Advisory· Published Mar 17, 2026· Updated Jun 17, 2026

CVE-2026-32294

CVE-2026-32294

Description

JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding SHA256 hash to pass verification.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Jetkvm/Kvm2 versions
    cpe:2.3:a:jetkvm:kvm:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:jetkvm:kvm:*:*:*:*:*:*:*:*range: <=0.5.3
    • (no CPE)range: <0.5.4
  • Jetkvm/JetKVMllm-fuzzy
    Range: <0.5.4

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.